Skip to main content

I need some help understanding the answer to a sample question in the Identity and Access Management Designer study guide.

 

Sample question:

Universal Containers (UC) has chosen to implement a hub-and-spoke Salesforce org strategy where a subset of users in the hub org should be able to access resources in any of the spoke orgs. The IT team at UC has decided they would like to manage users in the hub org and automatically create those  users in the spoke orgs, as needed, to reduce administrative burden. They will configure the hub org as an Identity Provider and use SAML to authenticate users in the spoke orgs. What is the recommended solution for automatically creating users in the spoke orgs?

 

The 2 best options are:

A. Use an IdP-initiated SAML flow and Custom SAML JIT Provisioning to create users in the spoke orgs.

B. Use an IdP-initiated SAML flow and Salesforce SAML JIT Provisioning to create users in the spoke orgs. 

 

The correct answer is to use the Custom option (A), but I don't see anything in the documents I've found on WHY the standard option wouldn't work.  Is it just the fact that the actual options on the SSO config screen say "Standard" and "Custom SAML JIT with Apex handler", or is there some other critical piece of information I'm overlooking in the question that would point to the need for a custom solution?

 

@Ladies Be Architects #Identity and Access Management 

4 comments
  1. Nov 30, 2018, 12:35 PM

    If the IdP connecting to the org for which we sign up SSO for is

    definitely providing all those required values including ProfileId or

    ProfileName - I believe some advanced identity management platform

    (Ping? Okta?) can do that, thus in that scenario you will use Standard

    JIT.

0/9000